CVE-2026-95847
Last modified
CVE-2026-95847 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map name as queue_ plus the client ID plus _meta.
Description
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map name as queue_ plus the client ID plus _meta. A durable session whose client ID ends in _meta can therefore make its message map collide with another client's metadata map. The colliding sessions read and write the same H2 MVStore map with incompatible value types, which can corrupt queue head and tail data and cause message loss, misdelivery, failed queue reloads, or exposure of queued content across sessions. This issue is fixed in version 0.18.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| moquette-io | moquette | < 0.18.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-95847?
How severe is CVE-2026-95847?
How do I fix CVE-2026-95847?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9584A security vulnerability has been detected in code-projects …7.3
- CVE-2026-95842Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,…8.7
- CVE-2026-95843Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,…8.7
- CVE-2026-95844Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,…8.7
- CVE-2026-95845Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,…8.7
- CVE-2026-95846Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,…8.7
- CVE-2026-95848Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,…9.3
- CVE-2026-9585An unauthenticated reflected cross-site scripting (XSS) vuln…8.6
- CVE-2026-9586An unauthenticated SQL injection vulnerability exists in San…9.8
- CVE-2026-95861A malicious actor with access to the network could exploit a…7.5
- CVE-2026-95862A malicious actor with access to the network could exploit a…7.5
- CVE-2026-95868A weakness has been identified in AdithyaYelloju Restaurant-…6.3
Are you affected by CVE-2026-95847?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
